Agent skill

Conducting Gdpr Compliance Assessment

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data…

Apache-2.0Auto-check passedLegal & Compliance

Install Conducting Gdpr Compliance Assessment

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-gdpr-compliance-assessment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills conducting-gdpr-compliance-assessment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/conducting-gdpr-compliance-assessment .claude/skills/conducting-gdpr-compliance-assessment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
conducting-gdpr-compliance-assessment
GitHub stars
34k
Token cost
~3.4k tokens
SKILL.md length
1,159 words
Files
9 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data…

  • Works in 9 steps: Determine Territorial Applicability… → Inventory Data Processing Activities… → Validate Lawful Basis (Article 6) → …
  • Processing personal data of EU residents
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 4 more sections
  • Runs Python scripts from its folder

What it does

Conducting Gdpr Compliance Assessment is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data subject rights implementation, Data Protection Impact Assessments (DPIAs) under Article 35, breach notification procedures, international transfer safeguards (SCCs, adequacy decisions), and technical/organizational measures under Article 32. Use when processing personal data of EU residents, preparing for supervisory…

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts, reference files and assets (for example `assets/compliance-scorecard.md`, `references/api-reference.md` and `references/detailed-workflow.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Processing personal data of EU residents
  • Preparing for supervisory authority audits
  • Implementing privacy-by-design for new systems
  • Scoping compliance gaps for M&A due diligence

Example prompts

  • “/conducting-gdpr-compliance-assessment”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Determine Territorial Applicability (Article 3)
  2. Inventory Data Processing Activities (Article 30)
  3. Validate Lawful Basis (Article 6)
  4. Assess Data Subject Rights (Articles 12-23)
  5. Review DPIAs (Article 35)
  6. Audit Breach Notification (Articles 33-34)
  7. Verify International Transfers (Chapter V)
  8. Assess Security Measures (Article 32)
  9. Compile Findings and Remediation Roadmap

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • edpb.europa.eu
    • commission.europa.eu

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Conducting Gdpr Compliance Assessment loads about 3.4k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 262 tokens; SKILL.md has 1,159 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~262
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,159 words, ~3,369 tokens.

Download SKILL.mdSave it as .claude/skills/conducting-gdpr-compliance-assessment/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
conducting-gdpr-compliance-assessment
description
Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data subject rights implementation, Data Protection Impact Assessments (DPIAs) under Article 35, breach notification procedures, international transfer safeguards (SCCs, adequacy decisions), and technical/organizational measures under Article 32. Use when processing personal data of EU residents, preparing for supervisory authority audits, implementing privacy-by-design for new systems, scoping compliance gaps for M&A due diligence, assessing third-party processors, or responding to data subject access requests at scale. Incorporates 2026 guidance from ICO, EDPB, and post-Data (Use and Access) Act 2025 UK-GDPR considerations. Do not use for implementing specific Article 32 controls — use implementing-gdpr-data-protection-controls; or for DSAR automation — use implementing-gdpr-data-subject-access-request.
domain
cybersecurity
subdomain
compliance-governance
tags
gdpr, data-protection, privacy, compliance, dpia, data-subject-rights, article-30, controller, processor, eu-regulation, ico, supervisory-authority
version
1.0
author
dakshverma23
license
Apache-2.0
nist_csf
GV.OC-02, GV.PO-01, GV.RM-04, PR.DS-01, PR.DS-02, ID.AM-05
mitre_attack
T1530, T1567

Conducting GDPR Compliance Assessment

Effective Date: August 2026
Legal Basis: EU Regulation 2016/679 (GDPR), UK GDPR as amended by Data Protection Act 2018 and Data (Use and Access) Act 2025 (ukpga/2025/18)
Pending Changes: Digital Omnibus proposal (COM(2025) 837) would change Article 30(5) threshold from 250 to 750 employees and Article 33 breach notification from 72h to 96h. Still in proposal stage; current requirements remain in force.

When to Use

  • When an organization processes personal data of EU residents (Article 3 territorial scope applies)
  • When preparing for a supervisory authority audit (ICO, CNIL, BfDI) or responding to formal inquiry
  • When implementing privacy-by-design requirements (Article 25) for new systems or data flows
  • When scoping compliance gaps before M&A due diligence or contract negotiations with EU entities
  • When responding to data subject access requests (DSARs) and discovering gaps in data inventory
  • When assessing third-party processors for GDPR compliance before signing Data Processing Agreements (DPAs)
  • After data breach incidents to verify notification procedures meet 72-hour requirement (Article 33)

Do not use for:

  • Technical implementation of specific GDPR controls (encryption, pseudonymization, access controls) — use implementing-gdpr-data-protection-controls for Article 32 technical/organizational measures
  • Automated DSAR processing workflows (identity verification, PII discovery, redaction, delivery) — use implementing-gdpr-data-subject-access-request for DSAR automation
  • Non-EU privacy frameworks alone (CCPA, PIPEDA, LGPD); those require separate assessments with jurisdiction-specific criteria
  • This skill is for comprehensive compliance assessment across all GDPR articles; use the specialized skills for focused implementation tasks

Prerequisites

  • Understanding of GDPR Articles 5-32 and key definitions
  • Access to Article 30 records of processing activities
  • Data Processing Agreements with third-party processors
  • Privacy policies, consent forms, cookie notices
  • Knowledge of lawful bases (Article 6)
  • Data breach response plan and incident register
  • List of international data transfers with safeguards

Workflow

For detailed procedures, templates, and examples, see references/detailed-workflow.md

Phase 1: Determine Territorial Applicability (Article 3)

GDPR applies if:

  1. Organization has establishment in EU
  2. Offers goods/services to EU residents
  3. Monitors behavior of EU residents

Check: EU office? EU website targeting? Behavioral tracking?

Phase 2: Inventory Data Processing Activities (Article 30)

Document for EACH activity:

  • Controller/processor details
  • Processing purposes (specific)
  • Data categories and special categories (Art. 9)
  • Recipients and international transfers
  • Retention periods
  • Security measures

Tools: Use scripts/article30_parser.py, article30_validator.py, generate_ropa_report.py

Common gaps: Missing retention periods (68%), vague purposes, undocumented transfers

Phase 3: Validate Lawful Basis (Article 6)
BasisUse CaseKey Requirement
Consent (6(1)(a))Marketing, profilingFreely given, specific, withdrawable
Contract (6(1)(b))Order fulfillmentStrictly necessary only
Legal Obligation (6(1)(c))Tax recordsCite specific law
Legitimate Interest (6(1)(f))Fraud prevention, analyticsThree-part test + balancing

Action: Map each Article 30 activity to one lawful basis. Document legitimate interest assessments.

Phase 4: Assess Data Subject Rights (Articles 12-23)

Verify capability for:

  • Access (15): Provide copy in machine-readable format within 1 month
  • Rectification (16): Correct inaccurate data
  • Erasure (17): "Right to be forgotten" (with exceptions)
  • Portability (20): Transfer data in structured format
  • Objection (21): Opt-out of legitimate interest processing
  • Automated Decision-Making (22): Human review of algorithmic decisions

Test: Process sample DSAR through full workflow. Use scripts/ for automation.

Phase 5: Review DPIAs (Article 35)

DPIA mandatory for:

  • Large-scale profiling with automated decisions
  • Large-scale special categories processing
  • Systematic monitoring of public areas (facial recognition)

Template: See references/detailed-workflow.md for complete DPIA structure

Content: Description, necessity, risks, mitigation, consultation (DPO, supervisory authority if novel high-risk)

Phase 6: Audit Breach Notification (Articles 33-34)

72-hour rule: Notify supervisory authority within 72 hours of becoming aware of breach likely to risk rights.

Decision tree:

  • Unencrypted SSNs stolen? → NOTIFY + notify data subjects
  • Encrypted backup stolen (key secure)? → Document only
  • Temporary exposure (2 hours, no financial data)? → NOTIFY authority, assess data subject notification

Content: Nature, categories/numbers, DPO contact, consequences, mitigation

Phase 7: Verify International Transfers (Chapter V)

Mechanisms:

  • Adequacy decisions (UK, Japan, etc.)
  • Standard Contractual Clauses (SCCs) 2021 + Transfer Impact Assessment
  • Binding Corporate Rules (BCRs)
  • Derogations (Article 49 - limited)

Post-Schrems II: Assess destination country surveillance laws, implement supplementary measures (encryption with EU-held keys)

Phase 8: Assess Security Measures (Article 32)

"Security appropriate to the risk":

  • Low risk: TLS 1.2+, password hashing, access logs, patching
  • Medium risk: AES-256 encryption, MFA, RBAC, penetration testing, SOC 2
  • High risk: HSMs, key rotation, SIEM, bug bounty, ISO 27001

Pseudonymization vs. Anonymization: Pseudo = reversible (still personal data); Anon = irreversible (no longer GDPR)

Show full SKILL.md (459 more words)Show less
Phase 9: Compile Findings and Remediation Roadmap

Generate compliance report:

  • Executive summary (overall status, high-priority gaps)
  • Article-by-article findings
  • Risk-prioritized remediation plan (Critical/High/Medium/Low)
  • Cost estimates and timelines
  • Responsible parties (DPO, IT, Legal, Business)

Format: See Output Format section below

Key Concepts

TermDefinition
ControllerDetermines purposes and means of processing (Article 4(7))
ProcessorProcesses on behalf of controller (Article 4(8); requires DPA per Article 28)
Personal DataAny information relating to identified/identifiable natural person (Article 4(1))
Special CategoriesHealth, biometric, genetic, racial, political, religious, trade union, sex life data (Article 9; heightened protection)
ConsentFreely given, specific, informed, unambiguous indication of wishes (Article 4(11))
Legitimate InterestLawful basis requiring three-part test: purpose, necessity, balancing (Recital 47)
DPIAData Protection Impact Assessment for high-risk processing (Article 35)
DPOData Protection Officer (Article 37; mandatory for public authorities, large-scale monitoring/special categories)
SCCsStandard Contractual Clauses for international transfers (Commission Implementing Decision 2021/914)
Supervisory AuthorityNational data protection regulator (ICO for UK, CNIL for France, BfDI for Germany)

Tools & Systems

Common Scenarios

Scenario: M&A Due Diligence

Context: Acquiring SaaS company with 50K EU customers. Need compliance assessment within 2 weeks.

Approach:

  1. Request Article 30 records + DPAs with processors (AWS, Stripe, Mailchimp)
  2. Validate lawful basis: Consent for marketing, Contract for service delivery
  3. Check breach notification procedures (Article 33): No procedures found → HIGH RISK
  4. Review international transfers: AWS US-East-1 without SCCs → BLOCKER
  5. Deliverable: Gap analysis with remediation costs ($120K for SCCs + DPO hire + breach procedures)
Scenario: Supervisory Authority Audit

Context: ICO formal inquiry after consumer complaint about unsubscribe not working.

Response:

  1. Produce Article 30 records within 7 days
  2. Demonstrate consent records (timestamp, version, scope)
  3. Show withdrawal mechanism (unsubscribe link functional, processed within 48h)
  4. Provide audit logs of DSAR/erasure requests
  5. Outcome: Warning + 3-month corrective order (no fine due to cooperation)

Output Format

GDPR COMPLIANCE ASSESSMENT REPORT
===================================
Organization: XYZ Corp | Assessment Date: 2026-08-24
Assessor: Jane Smith, CIPP/E | DPO: dpo@xyzcorp.com

EXECUTIVE SUMMARY
━━━━━━━━━━━━━━━━━
Overall Status: PARTIAL COMPLIANCE (67/100)
Critical Gaps: 3 | High: 5 | Medium: 8 | Low: 12

CRITICAL FINDINGS
━━━━━━━━━━━━━━━━━
1. Article 33: No breach notification procedures (72-hour deadline unmet)
2. Chapter V: International transfers to US without SCCs (Schrems II violation)
3. Article 30: Records incomplete (retention periods missing for 40% of activities)

ARTICLE-BY-ARTICLE STATUS
━━━━━━━━━━━━━━━━━━━━━━━━
✅ Article 3: Applicability confirmed (EU establishment)
⚠️  Article 6: Lawful basis documented but 3 activities use invalid bundled consent
✅ Article 15-23: DSAR procedures operational (18-day avg response time)
❌ Article 28: 40% of processors lack signed DPAs
⚠️  Article 32: Encryption at rest implemented but no MFA on admin accounts
❌ Article 33/34: No breach notification procedures
⚠️  Article 35: DPIA completed for profiling but not reviewed in 18 months
❌ Chapter V: US transfers without SCCs

REMEDIATION ROADMAP
━━━━━━━━━━━━━━━━━━━
Priority 1 (0-30 days, $50K):
  - Implement breach notification procedures + incident register
  - Execute SCCs with AWS, Stripe (Module 2)
  - Complete Article 30 records (retention periods, security measures)

Priority 2 (1-3 months, $80K):
  - Execute DPAs with remaining 8 processors
  - Deploy MFA on all admin accounts
  - Conduct legitimate interest assessments for analytics

Priority 3 (3-6 months, $40K):
  - Review and update DPIA
  - Automated DSAR response workflow
  - Annual GDPR training for staff

COMPLIANCE SCORE: 67/100 → Target 90/100 (6 months post-remediation)

Verification Checklist

  • Article 3 applicability determination documented
  • Article 30 records complete for all activities (controller + processor roles)
  • Lawful basis identified and documented for each activity
  • Legitimate interest assessments documented with balancing test
  • Consent mechanism is granular, withdrawable, and logged
  • Data subject rights procedures operational (1-month response time)
  • DPIA completed for high-risk processing (profiling, special categories, monitoring)
  • Breach notification procedures documented (72-hour timeline)
  • DPAs executed with all processors (Article 28 requirements)
  • International transfers use SCCs 2021 + Transfer Impact Assessment
  • Security measures appropriate to risk (encryption, MFA, logging, testing)
  • Retention periods defined and automated deletion implemented
  • Privacy policy published and updated within 12 months
  • DPO designated if required (Article 37 criteria met)
  • Staff trained on GDPR principles and data subject rights

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts, references, assets) in skills/conducting-gdpr-compliance-assessment of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/compliance-scorecard.md
  • references/api-reference.md
  • references/detailed-workflow.md
  • references/standards.md
  • scripts/article30_parser.py
  • scripts/article30_validator.py
  • scripts/generate_ropa_report.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Conducting Gdpr Compliance Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Conducting Gdpr Compliance Assessment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Conducting Gdpr Compliance Assessment this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Conducting Gdpr Compliance Assessment

What does Conducting Gdpr Compliance Assessment do?

Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data…. Conducting Gdpr Compliance Assessment is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data subject rights implementation, Data Protection Impact Assessments (DPIAs) under Article 35, breach notification procedures, international transfer safeguards (SCCs, adequacy decisions), and technical/organizational measures under Article 32.

When should I use Conducting Gdpr Compliance Assessment?

Conducting Gdpr Compliance Assessment fits situations like: processing personal data of EU residents; preparing for supervisory authority audits; implementing privacy-by-design for new systems; scoping compliance gaps for M&A due diligence.

How do I install Conducting Gdpr Compliance Assessment in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-gdpr-compliance-assessment -a claude-code`. Or copy the skill folder (skills/conducting-gdpr-compliance-assessment in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/conducting-gdpr-compliance-assessment in your project. Claude Code loads it when a task matches its description.

How do I install Conducting Gdpr Compliance Assessment in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-gdpr-compliance-assessment -a codex`. Or copy the skill folder (skills/conducting-gdpr-compliance-assessment in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/conducting-gdpr-compliance-assessment in your project. Codex loads it when a task matches its description.

Can I use Conducting Gdpr Compliance Assessment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-gdpr-compliance-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/conducting-gdpr-compliance-assessment, .gemini/skills/conducting-gdpr-compliance-assessment, .github/skills/conducting-gdpr-compliance-assessment and .opencode/skills/conducting-gdpr-compliance-assessment in your project.

What does Conducting Gdpr Compliance Assessment need to run?

Going by SKILL.md and its folder, Conducting Gdpr Compliance Assessment needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Conducting Gdpr Compliance Assessment access the network?

SKILL.md names 2 domains. As links in the text: edpb.europa.eu and commission.europa.eu. This is read from the text; nothing was executed.

Is Conducting Gdpr Compliance Assessment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Conducting Gdpr Compliance Assessment use?

Conducting Gdpr Compliance Assessment is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Conducting Gdpr Compliance Assessment use?

About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.3k tokens, read only when the agent opens those files.

What are the alternatives to Conducting Gdpr Compliance Assessment?

Skills that share tags, products or a category with Conducting Gdpr Compliance Assessment: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Conducting Gdpr Compliance Assessment?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.